Make me your Homepage
    left corner left corner
    China Daily Website

    US govt warns merchants on Target hacking tricks

    Updated: 2014-01-17 09:34
    ( Agencies)

    BOSTON ?- The US government on Thursday provided merchants with information gleaned from its confidential investigation into the massive data breach at Target Corp, in a move aimed at identifying and thwarting similar attacks that may be ongoing.

    The report titled "Indicators for Network Defenders" brings to light some of the first information gleaned from the government's highly secretive probes into the Target breach and other retail hacks, including details useful for detecting malicious programs that elude anti-virus software.

    "It's a shame this report wasn't released a month ago," said Dmitri Alperovitch, chief technology officer of the cybersecurity firm CrowdStrike. "It has been frustrating for some retailers because it has been incredibly difficult for most firms to get information. It has not been forthcoming."

    No. 3 US retailer Target disclosed the theft of some 40 million payment card numbers and the personal data of 70 million customers in a cyber attack that occurred over the holiday shopping season. Neiman Marcus last week said that it too was victim of a cyber attack, and sources have told Reuters that at least three other well-known national retailers have been attacked..

    The document noted that an underground market for malicious software to attack point-of-sale, or POS, terminals has flourished in recent years. Three of the most popular titles for the malicious software include BlackPOS, Dexter and vSkimmer.

    "We believe there is a strong market for the development of POS malware, and evidence suggests there is a growing demand," the report, obtained by Reuters, warned.

    The Secret Service, which is heading up the investigations into the cyber attacks, has declined to comment on what it has learned or identify victims besides Target and Neiman Marcus.

    ARMED WITH INFORMATION

    John Watters, chief executive of the security intelligence firm iSIGHT Partners, which helped draft the document released on Thursday, said that the government decided to provide information to retailers so they can determine whether their systems have been compromised by hackers.

    "The point of getting the technical artifacts out there is that people can go out there and examine their systems and see if they have been compromised," said Watters, whose firm has helped the Secret Service in its investigations of retail breaches. "Now they are armed with information and they can go do something about it."

    A Department of Homeland Security official said the report was drafted to provide the industry "with relevant and actionable technical indicators for network defense."

    The document said that an advanced piece of software dubbed the POSRAM Trojan, was used in the recent attacks.

    POSRAM is an type of RAM scraper, or memory-parsing software, which enables cyber criminals to grab encrypted data by capturing it when it travels through the live memory of a computer, where it appears in plain text.

    While the technology has been around for many years, its use has increased in recent years as retailers have improved their security, making it more difficult for hackers to obtain credit card data using other approaches.

    POSRAM succeeded in evading detection by anti-virus software when it infected the Windows-based point-of-sales terminals, according to the report.

    "This report was generated so that we could get it into the hands of commercial entities so that they had information they needed to protect themselves," iSIGHT Partners Senior Vice President Tiffany Jones told Reuters.

    The document was prepared by the Department of Homeland Security's National Cybersecurity and Communications Integration Center, the US Secret Service, iSIGHT Partners and the Financial Sector Information Sharing and Analysis Center, an industry security group.

    Alperovitch of CrowdStrike said that the report contained fewer technical details than an article published on Wednesday by security blogger Brian Krebs.

     
    Hot Topics
    The Party vowed on Wednesday to fight corruption firmly and to maintain its "high-handed posture" in the next five years.
    ...
    ...
    久久午夜无码鲁丝片秋霞| 国产成人无码A区在线观看视频| 日韩精品专区AV无码| 久久精品天天中文字幕人妻| 亚洲精品成人无码中文毛片不卡 | 亚洲中文字幕无码中文字在线| 亚洲av永久无码精品秋霞电影影院| 天堂新版8中文在线8| 亚洲色偷拍区另类无码专区| 秋霞鲁丝片Av无码少妇| 亚洲一区二区三区无码中文字幕| 日韩欧美中文在线| 日韩亚洲不卡在线视频中文字幕在线观看 | 中文精品无码中文字幕无码专区| 日韩高清在线中文字带字幕| 久久精品无码一区二区日韩AV| 日韩网红少妇无码视频香港| 亚洲国产综合无码一区| 亚洲欧美日韩中文字幕二区| 欧美视频中文字幕| 无码人妻精品中文字幕免费| 精品久久久久久中文字幕大豆网| 国产99久久九九精品无码| 国产三级无码内射在线看| 无码国产精品一区二区免费式芒果| 中文字幕无码播放免费| 区三区激情福利综合中文字幕在线一区亚洲视频1| 一级电影在线播放无码| 中文字幕无码高清晰| 精品久久久久久无码中文野结衣| 少妇人妻偷人精品无码视频| 无码人妻丰满熟妇区免费| 亚洲AV综合色区无码另类小说| 一区二区三区无码视频免费福利| 亚洲中文字幕不卡无码| 亚洲va中文字幕无码久久| 亚洲av无码一区二区三区网站| 亚洲国产无套无码av电影| 无码人妻久久一区二区三区免费丨| 无码人妻久久一区二区三区免费丨 | 无码人妻丰满熟妇区96|